Subprocessors
Effective date: 15 September 2026
This page is the list. It names every sub-processor that handles customer content, and it is Annex 3 of our Data Processing Agreement and Annex III for the purposes of the Standard Contractual Clauses.
The named list
| Sub-processor | Purpose | Processing location | Principal place of business | Contact |
|---|---|---|---|---|
| Google Cloud | hosting, storage, backups | europe-west regions | Gordon House, Barrow Street, Dublin 4, Ireland | via the Google Cloud privacy contact form |
| OpenAI | AI processing of selected task context | United States | 3180 18th Street, San Francisco, CA 94110, USA | [email protected] |
| Anthropic | AI processing of selected task context | United States | 548 Market Street, San Francisco, CA 94104, USA | [email protected] |
| Cloudflare | CDN and security edge, TLS termination | United States company, global edge network | 101 Townsend Street, San Francisco, CA 94107, USA | [email protected] |
The contracting entity for each is the one named in the signed data processing agreement, which may be a regional subsidiary of the company above. Ask us and we will tell you which entity holds your contract and send you the relevant terms.
If a provider is not in this table, it does not receive customer content. Adding or replacing an entry triggers 30 days’ notice by email, with a right to object, under DPA section 5.
What is deliberately not here. Providers that never see customer content are not sub-processors under the DPA: transactional email, support tooling, observability, and Google Analytics, which runs on the website and in the application behind separate consents but never receives repository content, reports or task context. They are described by category below and covered by the Privacy Policy, where we are the controller rather than your processor.
Agreements
Every sub-processor above is engaged under a data processing agreement incorporating the EU Standard Contractual Clauses and the UK Addendum.
| Sub-processor | Basis |
|---|---|
| Google Cloud | Google’s Cloud Data Processing Addendum, incorporating the EU SCCs and the UK Addendum. Processing is in europe-west regions, so no transfer out of Europe arises for storage |
| OpenAI | signed data processing agreement, EU SCCs and UK Addendum |
| Anthropic | signed data processing agreement, EU SCCs and UK Addendum |
| Cloudflare | Cloudflare’s data processing addendum, incorporating the EU SCCs and the UK Addendum, accepted on our account |
Which module applies depends on whose data it is. For customer content we are your processor and they are our sub-processor, so Module Three applies. For the data we control ourselves — the content of a support conversation, say — we are the controller and Module Two applies. The AI providers’ agreements cover both, which is why one signature was enough for each.
Changes to this page
The updated version is posted here with a new effective date. We keep previous versions of this page — ask and we will send you the one in force on any date you name.
Where processing happens
The Service runs on Google Cloud in its europe-west regions, and your data is stored in Europe and does not leave it at rest. Enji Guard is developed and operated by Enji AI LLC, registered in the Kyrgyz Republic, and sold through Paddle as merchant of record.
Four things reach outside Europe — our team, the AI providers, Cloudflare’s edge, and analytics. Privacy Policy §12 describes each of them and the safeguards that apply, and DPA section 10 carries what we commit to as your processor. This page names the providers.
Provider categories
Beyond the named list above, these are the categories of provider we use. The named list of the operational ones — those that never see your code or reports — is available on request, which keeps this page stable as vendors change.
- Repository hosting and integration — to connect repositories, verify access, and open issues and pull requests, using repository code and metadata for connected repositories.
- Authentication and sign-in — to manage account identity.
- Approved AI and coding providers — to run AI-assisted audits, using selected task context depending on the chosen route (see AI Data Use).
- Sale of credits and payment — Paddle, our authorised reseller and merchant of record, which takes card payments, determines and remits tax, issues receipts, and handles refunds and payment disputes. It receives billing contact details, billing address and country, any tax registration number, card details, and transaction records directly from you. Paddle acts as an independent controller for that data rather than as our processor, because it is the seller and carries its own tax, invoicing, and fraud-prevention obligations.
- Transactional email — to send product and notification emails, using recipient address and message metadata.
- Feedback and support tooling — to handle feedback and support messages, including any screenshots you provide.
- Analytics — Google Analytics, on the public website and inside the application, each behind its own consent, using visit and usage data on the site and product milestones in the app. Google is a United States company. It never receives your code or reports, which is why it is a category here and not a named sub-processor above. See the Cookie Policy.
- CDN and security edge — for TLS, delivery, and protection, using IP address and request metadata, and carrying customer content in transit as described above.
- Hosting and infrastructure — database, object storage, observability, and backup components operated to run the Service.
Enji Guard